2026 CVE Vulnerabilities
60,210 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8823 | LOW | 3.8 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests whi... |
| CVE-2026-8646 | CRITICAL | 9.1 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 ar... |
| CVE-2026-8636 | HIGH | 7.5 | 0.1% | Jun 22, 2026 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve use... |
| CVE-2026-8059 | MEDIUM | 6.1 | 0.1% | Jun 22, 2026 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site script... |
| CVE-2026-7664 | CRITICAL | 9.8 | 0.3% | Jun 22, 2026 | IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and... |
| CVE-2026-7253 | MEDIUM | 6 | 0.2% | Jun 22, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send ... |
| CVE-2026-56104 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and i... |
| CVE-2026-54268 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-54267 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-54266 | MEDIUM | 6.1 | 0.1% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-54265 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-54264 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-53655 | MEDIUM | 5.5 | 0.1% | Jun 22, 2026 | node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= recor... |
| CVE-2026-53550 | MEDIUM | 5.3 | 0.3% | Jun 22, 2026 | js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithm... |
| CVE-2026-52725 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50557 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50178 | HIGH | 8.8 | 0.2% | Jun 22, 2026 | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side... |
| CVE-2026-49241 | HIGH | 8.8 | 0.2% | Jun 22, 2026 | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4... |
| CVE-2026-41049 | HIGH | 7.1 | 0.1% | Jun 22, 2026 | Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed a... |
| CVE-2026-41048 | HIGH | 7.1 | 0.1% | Jun 22, 2026 | Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local at... |
| CVE-2026-41047 | MEDIUM | 5.5 | 0.1% | Jun 22, 2026 | Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacke... |
| CVE-2026-41046 | HIGH | 7.3 | 0.2% | Jun 22, 2026 | A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to... |
| CVE-2026-41045 | HIGH | 7 | 0.1% | Jun 22, 2026 | A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass... |
| CVE-2026-12725 | MEDIUM | 5.9 | 0.5% | Jun 22, 2026 | A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of... |
| CVE-2026-12628 | CRITICAL | 9.1 | 0.4% | Jun 22, 2026 | IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now